CVE-2014-7158: CSRF
Cross-site request forgery (CSRF) vulnerability in Exinda WAN Optimization Suite 7.0.0 (2160) allows remote attackers to hijack the authentication of administrators for requests that change the admin password via a request to admin/launch.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7158?
CVE-2014-7158 is classified as a medium severity cross-site request forgery (CSRF) vulnerability.
How do I fix CVE-2014-7158?
To fix CVE-2014-7158, you should upgrade to the latest version of Exinda WAN Optimization Suite that addresses this vulnerability.
Who is affected by CVE-2014-7158?
CVE-2014-7158 affects users of Exinda WAN Optimization Suite version 7.0.0.
What type of vulnerability is CVE-2014-7158?
CVE-2014-7158 is a cross-site request forgery (CSRF) vulnerability that allows unauthorized changes to administrator settings.
What can attackers do with CVE-2014-7158?
Attackers exploiting CVE-2014-7158 can hijack administrator authentication to change the admin password.